# ISO/IEC 27001 – Lightweight Control Mapping ## Scope This document maps **Federal FOIA Intelligence Search** to relevant ISO 27001 controls, scaled appropriately for a public, read-only research tool. --- ## A.5 Information Security Policies ✔ Public security posture documented ✔ No confidential data handled --- ## A.6 Organization of Information Security ✔ Single maintainer accountability ✔ Clear governance boundaries --- ## A.8 Asset Management | Asset | Classification | |----|----| | FOIA URLs | Public | | Metadata | Public | | User input | Ephemeral | --- ## A.9 Access Control ✔ No accounts ✔ No authentication ✔ No authorization layers --- ## A.12 Operations Security ✔ No background processing ✔ No scheduled jobs ✔ Stateless execution --- ## A.13 Communications Security ✔ HTTPS only ✔ No external data ingestion --- ## A.18 Compliance ✔ FOIA-compliant ✔ Copyright-safe (link-out only) ✔ Open-source transparency --- ## ISO Summary This system qualifies as **low-complexity, low-risk** under ISO 27001, with controls appropriate to scope.